There are some hackers here, but it's not_me..

Ask a question or request a feature related to the website or forum...

Moderator: scott

User avatar
path_finder
Addict
Addict
Posts: 2372
Joined: Wed Dec 10, 2008 9:32 am
Location: Paris (France)

There are some hackers here, but it's not_me..

Post by path_finder »

Dear all,
After review of the IP addresses obviously this forum is disturbed by several bots.
May be, even the owners of these infected PCs are absolutely ignorant of their zombie status.
(For those not in the game, a zombie is a computer infected with some malicious programs against your willing, and able in background to generate some spams or erratic attacks against some other people. A recent study detected a 15 years old teenager able to remotely control more than 12.000 private computers. See here for more infos: http://en.wikipedia.org/wiki/Zombie_computer).

A know some individuals here on this forum do have minor conflicts with other members.
Be careful, because it's not sure that the messages are really coming from the displayed name
Let's take per example the case of 'not-me' (a malicious joke's name):

The IP address 72.21.196.66 is used sometime by:
- Mr Roger GODOGO, from the TOGO, and chatting on the Web site
subject: 'le club de Rhum' (The Rome Club of the donors), a real joker...
source: www.togosite.com
- Mr Rajesh MUNNURU, aka Telugu_moviefan
Username: Telugu_moviefan
Full Name: Rajesh Munnuru
E-mail Address: rajesh.moviefan@gmail.com
Last Logged In: April 07, 2010
Registered: April 03, 2009
Total Posts: 1649
Status: Above Average
source: http://www.tollywoodinfo.com/cgi-bin/di ... efan-users
- Mr Rob HICKS, email: withywindle72@yahoo.com
source: http://www.voy.com/119253/267.html

In addition there are some bots users recorded for the IP address 72.21.196.66
using this two malicious bot softwares
Mozilla/5.0 (compatible; AMZNKAssocBot/4.0)
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko/20091106 Shiretoko/3.5.5 (.NET CLR 3.5.30729)
source: http://www.projecthoneypot.org/ip_72.21 ... sj2psq23e2

Obviously there is a hacker using this address through another computers, this guy is driving a big population of zombies.
see here few complaining infected people: http://forums.whirlpool.net.au/forum-re ... 41629.html, after the middle of the URL (sbobz user etc)
(all are redirected on the same IP address: 72.21.196.66)
It seems to be a paranoiac, sending some messages anonymous at the name of real members, and with a polemical content in view to let fight the people together and/or increase the level of noise.

So far, with modesty, I can recommend:

- to not_me (not the hacker using this name, but the infected member):
1. Review your computer with a perfect antivirus software, and almost with an anti-rootkit.
2. Update your Web navigator with the latest version (for Firefox a new version has been released last week)
3. Verify your IP address (solong 72.21.196.66 detected, solong you are infected)
not by looking inside you computer but by asking www.ip-adress.com or whatismyipaddress.com
4. Inform Scott on your new IP address.
5. Stop to contest everything, the people you are in front being NOT what you believe...

- to all: verify the origin of the post you see on the screen.
If it is 72.21.196.66, forget it. Don't answer at all.

- to Scott:
1.Block all messages coming from this IP address (recognized as blacklisted by many sites).
2.Inform the antispam/abuse specialized sites about these troubles.

The bad climate observed since few weeks should be changed.
I cannot imagine why nobody though on this before, including myself? It is so simple!...
User avatar
LustInBlack
Devotee
Devotee
Posts: 1964
Joined: Thu Apr 06, 2006 10:30 am

re: There are some hackers here, but it's not_me..

Post by LustInBlack »

So you are basically saying that not_me (the real user) reads messages differently than the one we read on the forum!?

Like a kind of filter that changes the meaning of the posts of the forum to something offensive!? ..

That's quite interesting to say the least.. I am quite interested in this worm, or zombie if you wish .. 8]

Btw, the IP is sometimes meaningless, if the user uses a proxy, or a public access point or 3G networks, or even if the ISP changes the IP often...
User avatar
path_finder
Addict
Addict
Posts: 2372
Joined: Wed Dec 10, 2008 9:32 am
Location: Paris (France)

re: There are some hackers here, but it's not_me..

Post by path_finder »

Dear LustinBlack,
you said
even if the ISP changes the IP often
That the point, because not_me seems to have kept the same IP (72.21.196.66) during a long time. If connected through DHCP, he should have many.

What I said is only a suggestion: some messages have been sent by the hacker, 'in personna' of not_me, stealing it's IP (the identity usurpation on Internet is easy).
My assumption is based on the numerous population of surfers using the same blacklisted IP. Now some members can also play a jeopardized game...
I cannot imagine why nobody though on this before, including myself? It is so simple!...
Ralph_Lortie
Dabbler
Dabbler
Posts: 12
Joined: Mon Apr 12, 2010 9:37 pm

re: There are some hackers here, but it's not_me..

Post by Ralph_Lortie »

Scott and all of interest,

I rlortie being unable to get 'log in recognition' using the same user name and password in excess of five years, has re-registered as Ralph_Lortie...

I attempted changing passwords and that was prevented by being told that the address was already registered to someone else? Am I a victim of Path_finders Zombies?

After re-registering a check in memberlist does not show that rlortie ever existed on this forum! Have I been banned and deleted.

Also when clicking on http://www.besslerwheel.com/forum/viewtopic.php?t=21 I am told that there is no 275 postings on that thread.

EDIT: rlortie no longer exists as a member and any record of having an album is missing!

Ralph_Lortie
aka rlortie
aka rlortie@arrache.org
User avatar
LustInBlack
Devotee
Devotee
Posts: 1964
Joined: Thu Apr 06, 2006 10:30 am

re: There are some hackers here, but it's not_me..

Post by LustInBlack »

I think there was a database error.. The site has been very slow for a while.

That, or someone is doing a DoS on BW ..
Ralph_Lortie
Dabbler
Dabbler
Posts: 12
Joined: Mon Apr 12, 2010 9:37 pm

re: There are some hackers here, but it's not_me..

Post by Ralph_Lortie »

Farther research has shown that rlortie never existed on this forum.

Member listing no longer exists.
All posts are gone.
Arrache avatar never existed
No one by that name with a "highly regarded" reputation ever existed.
And if that is not enough all his jokes in the "Off Topic" joke thread are gone.

When I click on the last entry on any thread, I am told that no posts are present in that thread. I have to start with page one and work my way up.

I do believe that rlortie is the poltergeist you have been looking for!

Can anyone find me, or am I totally a none existing person?

Ralph
Formerly known as rlortie in a past life!
User avatar
LustInBlack
Devotee
Devotee
Posts: 1964
Joined: Thu Apr 06, 2006 10:30 am

re: There are some hackers here, but it's not_me..

Post by LustInBlack »

Who are you !?

;P
ovyyus
Addict
Addict
Posts: 6545
Joined: Wed Nov 05, 2003 2:41 am

re: There are some hackers here, but it's not_me..

Post by ovyyus »

Who are you talking to LIB?

:D
User avatar
LustInBlack
Devotee
Devotee
Posts: 1964
Joined: Thu Apr 06, 2006 10:30 am

re: There are some hackers here, but it's not_me..

Post by LustInBlack »

I don't know, some new member I guess..

I'll red dot him...
Ralph_Lortie
Dabbler
Dabbler
Posts: 12
Joined: Mon Apr 12, 2010 9:37 pm

re: There are some hackers here, but it's not_me..

Post by Ralph_Lortie »

LIB,

Red dot away because he no longer belongs to any private forums, not even his own! Apparently I fell into Beardon's Zero energy field.

Ralph
User avatar
LustInBlack
Devotee
Devotee
Posts: 1964
Joined: Thu Apr 06, 2006 10:30 am

re: There are some hackers here, but it's not_me..

Post by LustInBlack »

Seriously, don't worry Ralph, I'm pretty sure Scott got some backup ..
FunWithGravity2
Devotee
Devotee
Posts: 1040
Joined: Thu Jul 24, 2008 10:32 pm

re: There are some hackers here, but it's not_me..

Post by FunWithGravity2 »

Private forums, I was going to ask why i couldn't see yours last week. Your OLD name was highlighted as a mod but i was blind to a Rlortie group.


PS ralph, cmon, you know the rules on sock puppets LOL :)


Maybe the ghosts that chucked you from OU.com decided to harrass you over here, Or maybe the powers that be have been sweeping your hardrive every night and have realised your about to release a secret that could change the world. I would head down to the bunker and start making videos right now.

"thet thers funi i dunt kare whoo ya R"
Si mobile in circumferentia circuli feratur ea celeritate, quam acquirit cadendo ex
altitudine, quae sit quartae parti diameter aequalis ; habebit vim centrifugam suae
gravitati aequalem.
justsomeone
Addict
Addict
Posts: 2098
Joined: Tue Dec 30, 2008 5:21 pm

re: There are some hackers here, but it's not_me..

Post by justsomeone »

Dave,

I think they are on to you also.

I just clicked on " various MT thoughts " and all I get is " No posts exist for this topic ".
User avatar
jim_mich
Addict
Addict
Posts: 7467
Joined: Sun Dec 07, 2003 12:02 am
Location: Michigan
Contact:

Post by jim_mich »

Ralph, the forum database has been corrupted. Your old user ID number was 244. Hopefully Scott has backup files to repair the database.

http://www.besslerwheel.com/forum/profi ... file&u=243 (spinner) OK
http://www.besslerwheel.com/forum/profi ... file&u=244 (rlortie) Produces an error message.
http://www.besslerwheel.com/forum/profi ... file&u=244 (Winkle) OK

Ralph, it looks like you no longer exist.
Maybe "they" are out to get you?

Image
FunWithGravity2
Devotee
Devotee
Posts: 1040
Joined: Thu Jul 24, 2008 10:32 pm

Re: re: There are some hackers here, but it's not_me..

Post by FunWithGravity2 »

justsomeone wrote:Dave,

I think they are on to you also.

I just clicked on " various MT thoughts " and all I get is " No posts exist for this topic ".
Don't worry, you just have to go back to page 32, my "guess" would be that the people that were erased had their posts removed and this shortened some topics. since the number went down then the last two pages have not been written yet. Holy mackeral how often can you rewrite history.


I'm sure problems like this are popular with sites without HUGE budgets and support systems. I always wondered why Coylo had only 22 posts although it would seem like he had many more. Maybe coylo is a replacement name for those that have been abducted, Sorry coylo, i mean Rlortie.


Ralph i may have given you some advice i regret, forget the bunker head for the hills and bring your guns.
Si mobile in circumferentia circuli feratur ea celeritate, quam acquirit cadendo ex
altitudine, quae sit quartae parti diameter aequalis ; habebit vim centrifugam suae
gravitati aequalem.
Post Reply